← Hover

Hover — Privacy Policy

Last updated: 3 October 2026

Hover is a browser extension that lets you trade tokens directly from X (Twitter). This policy explains exactly what the extension does and does not do with your information.

The short version: Hover works without an account with wallets you connect yourself. If you choose Connect X, Hover creates an optional social identity and a separate Bankr-powered managed Hover Wallet. Connected-wallet keys never leave those wallets. Hover Wallet uses a scoped Bankr credential encrypted on our server; the extension never receives that credential or a private key. Your settings and swap history live on your own device. Our backend also receives optional social data, anonymous usage events, the public blockchain facts needed to certify Hover Points, and any share card you explicitly publish.


1. Two wallet modes

Connected wallets are self-custodied. The following two bullets apply to connected-wallet actions only:

Hover Wallet is managed. If you connect X, Hover provisions a separate wallet through Bankr. Bankr manages its signing infrastructure. Hover stores a wallet-specific Bankr API credential encrypted with AES-GCM on our backend; it is decrypted only inside the authenticated wallet service and is never returned to the browser. The credential is limited to Bankr's Wallet API, with agent, token-launch, and LLM access disabled.

2. What is stored on your device

Hover stores the following locally, using your browser's extension storage. It stays on your device and is not transmitted to us.

Stored What it is
Connected wallet addresses The public address and wallet name (e.g. "Phantom") of wallets you connect. Public addresses only — never keys.
Swap history Your Hover trades: tokens, amounts, transaction hashes, chain, timestamp, status.
Holdings preferences How your positions are ordered, which ones you chose to hide, and small positions you chose to show anyway.
Settings Slippage tolerance, quick-buy amounts, quick-sell percentages, on/off state.
Optional X session If you connect X, the Supabase session tokens and a cached copy of your X handle, display name, and avatar needed to keep you signed in.
Hover Wallet summary Its public EVM/Solana deposit addresses, readiness state, and your choice of connected or managed wallet for swaps. The Bankr credential is never stored in browser storage.

Settings and preset amounts use Chrome's synced extension storage, so they follow your Chrome profile across your own signed-in browsers. That syncing is performed by your browser, not by us.

You can erase all of it at any time by removing the extension, which deletes its storage.

3. What leaves your browser, and to whom

Most of what Hover fetches goes directly from your browser to the third-party services below; we do not receive copies of those requests. What our own backend receives is limited to the items marked "our backend" in this section — optional X identity and social data, anonymous usage counts, leaderboard certification, ticker resolution, tips lookups, and shares you explicitly publish.

Market and token data — token addresses, tickers, and chain identifiers are sent so prices, charts, and token details can be returned:

Blockchain reads — your public wallet address is sent to read balances, list your holdings, and confirm transactions. Because Hover supports eleven chains, a single balance refresh may contact several of these at once:

Building a connected-wallet trade — when you request a connected-wallet quote, your public wallet address is sent to the router (Jupiter or LI.FI) because a signable transaction must be addressed to you. Jupiter also receives it when Hover refreshes your connected Solana balances. No key material is involved. Managed-wallet actions follow the separate Bankr flow below.

Managed Hover Wallet (Bankr and our backend) — if you connect X, our backend sends Bankr a pseudonymous, one-way identifier to provision one wallet, and stores the resulting public addresses and encrypted wallet-specific API credential. Bankr receives managed-wallet portfolio reads and the token, chain, amount, slippage, and destination required for actions you explicitly request. For EVM withdrawals, Bankr also receives the recipient address. Bankr does not receive your X handle from this flow. See Bankr's own privacy and security terms for its processing and signing infrastructure.

Safety screening — when a token is screened, its contract address (not your address) is sent to GoPlus (api.gopluslabs.io) and RugCheck (api.rugcheck.xyz).

Name lookups — when displaying a .sol or .eth name, the relevant address or name is sent to Bonfida (sns-api.bonfida.com, sns-sdk-proxy.bonfida.workers.dev) or ENS Ideas (api.ensideas.com).

Optional X identity and social features (X and our backend) — Hover remains fully usable without this feature. If you choose Connect X, X authenticates you through Supabase Auth and provides your X user ID, handle, display name, and avatar. Hover stores that profile, your Hover follow relationships, social preferences, referral relationship, notification state, and the public wallet addresses you separately prove you control by signing a short-lived nonce. One wallet can belong to only one Hover identity. Hover never receives your X password, direct messages, or permission to post as you.

Your X handle, display name, avatar, Hover follower counts, and presence on Hover may be visible to other Hover users. If activity sharing is on, your linked public wallets, certified Hover activity, amount visibility choice, and Identity HP may also appear in profile cards, Circle, token context, and other social surfaces. You can turn activity sharing off without affecting your wallet's certified HP.

Anonymous usage counts (our backend) — so we can answer "how many installs, how many swaps" without accounts, the extension sends our backend an event when it is first installed and when a swap confirms. A swap event carries a random per-install identifier, the chain, the public contract address and ticker of the token traded, the trade direction, and a rounded USD amount. It never carries your wallet address, transaction hash, or any account identity; the identifier is generated on your device, is linked to nothing else, and resets if you clear the extension's storage.

Hover Points and the leaderboard (our backend) — Hover Points belong to a wallet and are certified against the blockchain rather than taken on trust. When a swap you made through Hover confirms, the extension sends our backend your public wallet address, the chain, the transaction hash, and — if you left the credit checkbox ticked — the X handle of the post that surfaced the token, so the swap can be verified on-chain and credited. These are public facts already visible on the blockchain. This certification flow receives no key or signing authority. Wallets with points appear on the public leaderboard by address, and your address is sent when the extension asks for your own rank. Reads for the live board, ticker resolution ("cashtags") and remote configuration carry no identity.

Tips feature (our backend) — if you use tipping, the X handle you are tipping is sent to our backend to look up an associated public address. We do not store a record of who tipped whom.

Sharing a trade — sharing is entirely optional and happens only when you press Share on a completed trade. Nothing is ever uploaded for trades you don't share. When you do share, Hover publishes to our backend:

These exist to render the public link page your post carries, so they are publicly readable and effectively permanent — that is what a share is.

A trade share does not carry your wallet address. A rank share — the card showing your leaderboard standing — does: your public wallet address is printed on the card itself, because the rank it displays belongs to that wallet. Your leaderboard standing is public by address in any case, so a rank share can be traced back to the wallet that published it. Share a rank card only if you are content to link that wallet to the account you post from.

Uploads are validated and rate-limited server-side. If you never press Share, this section does not apply to you.

Each of these services has its own privacy policy and its own logging practices, which are outside our control.

4. Your choices, retention, and deletion

Wallet-only Hover does not require X sign-in. If you connect X, you can sign out, unlink wallets from the identity, disable tips, choose whether swaps are shared, and choose whether shared amounts are exact, ranged, or hidden. Signing out removes the local session but does not delete a funded Hover Wallet or its server record. Before requesting wallet closure, transfer out supported assets; closing a Bankr wallet is permanent and assets left at its addresses may become inaccessible. Certified transaction facts and public share links may need to remain for leaderboard integrity, fraud prevention, and the permanence of links you deliberately published.

To request deletion of your optional Hover identity and associated social data, email onhoverxyz@gmail.com from a method we can use to verify the request. Public blockchain records cannot be deleted, and independently cached or reposted public shares may remain outside our control.

5. What we do not do

6. Where Hover runs

Hover's content script is restricted to x.com and twitter.com. It does not run on any other website.

7. Children

Hover is not directed to children and is not intended for anyone under 18.

8. Changes

If this policy changes materially, the updated version will be published here with a new "Last updated" date, and the extension listing will reflect it.

9. Contact

Questions about this policy: onhoverxyz@gmail.com